Parser
Most recent version: v0.4.1
Last updated
Was this helpful?
Most recent version: v0.4.1
Last updated
Was this helpful?
The Parser Action gives structure to and divides a JSON, Key-Value, CSV, Delimited Values, or Fixed Length file into separate fields.
These are the input and output ports of this Action:
Find Parser in the Actions tab (under the Transformation group) and drag it onto the canvas.
To open the configuration, click the Action in the canvas and select Configuration.
Enter the required parameters:
Select field to parse*
First, choose the field to parse from your input data by typing it in the search bar or selecting it from the list.
Input*
This is where you specify how to read the incoming data:
real_data - this is the data taken directly from the linked Listener.
paste - there may be times that you will receive a file with updated data for the Listener. If this is the case, you can paste it here.
In the Events drop-down, you can write how many events to show in this window.
Now you have specified where to source the data from, you need to determine how to process the events.
Parser*
There are two ways to parse your data:
auto - automatically parses all key-value fields.
manual - manually split fields and rename them.
Now we have decided which field, from where, and how to parse, we need to specify the interpretation of the output to the next action.
Output*
Here you can see the raw message that has been generated.
Here you can change the data type and edit the field name.
For fields containing subfields (field.subfield
), changing the field name will change all of the prefixes.
Click Save to complete the process.
Learn how to use the Parser with this example.
We have opened the configuration of the Parser to our Pipeline, which receives data from the linked Listener.
First we must select the field to parse from the Listener to separate into more specific data. This is the field containing the raw data.
In the Input field, select Real data if you feel comfortable with how the Parser works.
Select Paste and paste this log to follow along with us for the various examples of log sources.
A CSV file using "," as a separator
Log to paste
Select Auto to automatically parser this data into separate fields.
The parser will automatically parse the log, having recognized the separator. The default values will be fieldName1,2,3 etc.
Now we have decided which field, from where, and how to parse, we need to specify how it is output to the next action. In the output field, we can change the names of each field.
TIMESTAMP
HOSTNAME
EVENT TYPE
PROCESS NAME
PROCESS ID
USERNAME
IP ADDRESS
HASH
THREAT SCORE
Click Save.
In order to configure this action, you must first link it to a . Go to to learn how to link.
Here you can view the fields as a list, or as code. Each data type has a color. Learn more .
The language and grammar used to parse is PCL (Parser Configuration Language). We have provided an extensive run-down of each command .
Below, each individual field is according to the legend and separated into its type and name.